# Filebeat.yml logging issue

**URL:** <https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 30, 2019, 9:58pm UTC](https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386 "2019-12-30T21:58:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RunningSmurf](https://avatars.discourse-cdn.com/v4/letter/r/0ea827/32.png) [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Post date:** [December 30, 2019, 9:58pm UTC](https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386/1 "2019-12-30T21:58:57Z")

</div>

Hello,

I noticed that my filebeat beat was not producing a log file. I realized that I never set a filename, path, etc... I set the following, but I get the following error with the file path:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a40ea7d0d81afcf936b11dd9d2eab17f41d6633d.png)

Any suggestion would be greatly appreciated.

Sincerely,

RS

---

<div class="post-metadata">

**Author:** ![Saif\_Ur\_Rehman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saif_ur_rehman/32/60111_2.png) [@Saif\_Ur\_Rehman](https://discuss.elastic.co/u/Saif_Ur_Rehman)\
**Post date:** [December 30, 2019, 10:28pm UTC](https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386/2 "2019-12-30T22:28:59Z")

</div>

This is my code of filebeat.yml and is working perfectly. Hope this works, If doesnot then look for the other integrations you are doing with filebeat.

filebeat.inputs:

- type: docker  
combine\_partial: true  
containers:  
path: "/usr/share/dockerlogs/data"  
stream: "stdout"  
ids:  
- "\*"  
exclude\_files: ['.gz$']  
ignore\_older: 10m

processors:

# decode the log field (sub JSON document) if JSON encoded, then maps it's fields to elasticsearch fields

- decode\_json\_fields:  
fields: ["log", "message"]  
target: ""
# overwrite existing target elasticsearch fields while decoding json fields
overwrite\_keys: true
- add\_docker\_metadata:  
host: "unix:///var/run/docker.sock"

filebeat.config.modules:  
path: ${path.config}/modules.d/\*.yml  
reload.enabled: false

# setup filebeat to send output to logstash

output.logstash:  
hosts: ["logstash"]

# Write Filebeat own logs only to file to avoid catching them with itself in docker log files

logging.level: error  
logging.to\_files: false  
logging.to\_syslog: false  
loggins.metrice.enabled: false  
logging.files:  
path: /var/log/filebeat  
name: filebeat  
keepfiles: 7  
permissions: 0644  
ssl.verification\_mode: none

---

<div class="post-metadata">

**Author:** ![RunningSmurf](https://avatars.discourse-cdn.com/v4/letter/r/0ea827/32.png) [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Post date:** [December 31, 2019, 7:22pm UTC](https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386/3 "2019-12-31T19:22:12Z")

</div>

Thank you for your reply. I think that the issue is the path to the log file and the fact that it contains spaces. Regardless of the types of quotes I use, I still get this error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2020, 7:22pm UTC](https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386/4 "2020-01-28T19:22:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
